Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

101–110 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#101

Earlier quoted context omitted.

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

Then perhaps MS ought to shorten its bug fixing period. Three months is quite a long time to find a bug, fix it, and run extensive tests. What good is a fixed time period if you're willing to extend it just because one company can't pull their shit together? As for the Kaminsky DNS bug, it was leaked more than a solid week ahead of the time he intended to release it. Sure, patches had already been released, but how a…

Everybody is saying that 90 days is too much, even at MS' scale. So, taking into account that everybody seems to know very well what MS has to support, what is a good number of days to finish all the work that needs to be done?

Re: Google discloses another Windows security issue after deadline exceeded

#103

Earlier quoted context omitted.

Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.

Google roughly supports one version of their product on 2 OSs. Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame. Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues. It's easy for Google to…

> Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.

IIRC Microsoft also releases pre-versions of their patches to select customers so sysadmins can test the patch doesn't cause issues on their deployments.

Re: Google discloses another Windows security issue after deadline exceeded

#104
post #19

In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...

Little known fact: since lollipop, the webview is now upgradeable: https://developer.android.com/about/versions/lollipop.html#W... . So in two years, it will be a thing of the past. And regressions of old-apps using new-webview will be a real issue.

Re: Google discloses another Windows security issue after deadline exceeded

#105
post #104
post #19

In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...

Little known fact: since lollipop, the webview is now upgradeable: https://developer.android.com/about/versions/lollipop.html#W... . So in two years, it will be a thing of the past. And regressions of old-apps using new-webview will be a real issue.

So in two years, it will be a thing of the past.

AHAHAHAHAHAHAHAHAHAHAHA

Re: Google discloses another Windows security issue after deadline exceeded

#106

Earlier quoted context omitted.

Then perhaps MS ought to shorten its bug fixing period. Three months is quite a long time to find a bug, fix it, and run extensive tests. What good is a fixed time period if you're willing to extend it just because one company can't pull their shit together? As for the Kaminsky DNS bug, it was leaked more than a solid week ahead of the time he intended to release it. Sure, patches had already been released, but how a…

Everybody is saying that 90 days is too much, even at MS' scale. So, taking into account that everybody seems to know very well what MS has to support, what is a good number of days to finish all the work that needs to be done?

90 days seems just fine. What they need to do is give greater importance to bugs and apply more resources accordingly.

When it actually affects them, they aren't hesitant to do whatever the hell it takes, with no regards as to the consequences for others, with zero warning at all, as was shown during the whole fiasco when they effectively took down NoIP's services. Meanwhile, when Google holds them to a perfectly reasonable deadline, for the extremely valid reason that bugs should be fixed on time, Google is evil?

Given their scale, they can afford to dedicate larger teams of people to the task of fixing security vulnerabilities. They can afford to hire independent security researchers and whatnot to help them find and fix such vulnerabilities.

If they need to break some third-party application in fixing a security vulnerability, that's okay. Because that application can also be fixed by its developer, and security needs come ahead of an app here or an app there. Besides, it isn't as if users of Microsoft's products are not used to the concept of having stuff break all the time anyways.

Have you noticed how quickly MS starts releasing patches and updates when a 0day comes out? That shows that they are clearly capable of doing whatever they need to do pretty damn quickly. They just don't do that with all security vulnerabilities, due to "business reasons", and as a result their customers suffer.

Re: Google discloses another Windows security issue after deadline exceeded

#107
I can understand both points of view with the disclosure of the security issue. A while ago I discovered some security issues with Adobe ColdFusion and Railo. I wish I had put a deadline on disclosing the Adobe ColdFusion issues, as they dragged their feet so much (with admitting it was an issue and progressing with a fix) that at points I felt like throwing in the towel. Regrettably, instead of lighting a fire under their ass, I waited. At the time I was working on an open source side project, which would have pointed fingers towards where the issue was for any curious people.

I ended up halting development of my project while I waited for Adobe, to the point where I no longer wanted to work on it. I had stopped for too long and I didn't want to dig anything else up. Having no legal type knowledge myself or knowing anyone who could offer such advice, I was also too concerned to reveal anything for fear or any legal reprise.

So, the threat of security disclosure is warranted to pressure others into putting in the effort. However, the impact of the disclosure should be considered. If it will seriously affect others (who aren't responsible for the fix) and put them at risk, there should be the flexibility there to work with them on a deadline.

Re: Google discloses another Windows security issue after deadline exceeded

#108
post #72

Earlier quoted context omitted.

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

> others that Microsoft would just put off fixes forever if Google didn't do this. People wouldn't think that if MS didn't have a long history of doing exactly that.

What security fixes has Microsoft put off forever?

Re: Google discloses another Windows security issue after deadline exceeded

#109
Everyone here seems to have this idea that MS should be able to validate and test a fix for all of their platforms and then publish it via their normal channels within the 90 days...That would actually mean that they only had 60+ days to get it fixed before the next patch Tuesday. But whatever, I just don't see why they can't work with MS to make sure that if a patch is in progress that the public disclosure gets delayed.

This could end up going very badly for customers at some point in the near future. Could you imagine if google had published POC code for the SCHANNEL bug that came out lat year? You would have seen worms and new botnets immediately. That doesn't really help the situation. If they've committed to a fix, let them get it out before the public disclosure.

In the end, MS has a support task that is unlike anything else in the tech industry. If they are trying to do the right thing, and they have really improved here, why beat them over the head with it?

Re: Google discloses another Windows security issue after deadline exceeded

#110

Earlier quoted context omitted.

Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…

Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.

IIRC they do issue out-of-schedule patches if a vulnerability is severe enough and/or being actively exploited.
Post reply on HN